Leisure Coast Kitchens: Exclusive: Shellharbour-based Leisure Coast Kitchens listed by Kairos ransomware group

Leisure Coast Kitchens: Exclusive: Shellharbour-based Leisure Coast Kitchens listed by Kairos ransomware group

Kairos Ransomware Group Strikes Australian Kitchen Design Firm, Steals 540GB of Data

The Kairos ransomware group has claimed another Australian victim, targeting Leisure Coast Kitchens, an NSW-based kitchen design and renovation firm. On 16 September, the hackers posted a leak announcement, alleging they exfiltrated 540GB of sensitive data from the company.

As proof of the breach, Kairos published several files, including:

  • Employee driver’s license scans
  • A company balance sheet
  • Customer correspondence with names and contact details
  • A completed tax file number declaration
  • An employee’s personal details, including bank account numbers and emergency contacts

Kairos has not disclosed a ransom amount but has threatened to release the full dataset within six days. Leisure Coast Kitchens has not responded to requests for comment.

About Kairos

First detected in November 2024, Kairos has claimed 96 victims to date, though its activity remains relatively low compared to larger ransomware groups. The group typically gives victims seven days to pay, offering a discount for prompt compliance.

This marks Kairos’ second recent attack in the ANZ region, following the July breach of Warwick Fabrics, the New Zealand arm of a global textile supplier. Its most recent Australian victim was LR Reed, a property management firm.

About Leisure Coast Kitchens

Based in Oak Flats, Shellharbour (Illawarra region), the company specializes in kitchen design, construction, and renovations, as well as home offices, outdoor areas, and laundries. It partners with local builders, including Stroud Homes and the Evolution Building Group.

Source: https://www.cyberdaily.au/security/14200-exclusive-shellharbour-based-leisure-coast-kitchens-listed-by-kairos-ransomware-group

Cederberg Kitchens + Renovations cybersecurity rating report: https://www.rankiteo.com/company/cederberg-kitchens-renovations

"id": "CED1789698286",
"linkid": "cederberg-kitchens-renovations",
"type": "Ransomware",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Customers with exposed '
                                              'correspondence',
                        'industry': 'Kitchen Design and Renovation',
                        'location': 'Oak Flats, Shellharbour, NSW, Australia',
                        'name': 'Leisure Coast Kitchens',
                        'type': 'Private Company'}],
 'data_breach': {'data_exfiltration': 'Yes (540GB exfiltrated)',
                 'file_types_exposed': ['Scans', 'Documents', 'Spreadsheets'],
                 'personally_identifiable_information': 'Yes (names, contact '
                                                        'details, bank account '
                                                        'numbers, TFN)',
                 'sensitivity_of_data': 'High (PII, financial, and corporate '
                                        'data)',
                 'type_of_data_compromised': ['Employee driver’s license scans',
                                              'Company balance sheet',
                                              'Customer correspondence',
                                              'Tax file number declaration',
                                              'Employee personal details (bank '
                                              'account numbers, emergency '
                                              'contacts)']},
 'date_detected': '2024-09-16',
 'date_publicly_disclosed': '2024-09-16',
 'description': 'The Kairos ransomware group targeted Leisure Coast Kitchens, '
                'an Australian kitchen design and renovation firm, '
                'exfiltrating 540GB of sensitive data. The group published '
                'proof of the breach, including employee and customer data, '
                'and threatened to release the full dataset within six days.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage',
            'data_compromised': '540GB of sensitive data',
            'identity_theft_risk': 'High (employee and customer PII exposed)',
            'legal_liabilities': 'Potential legal liabilities due to data '
                                 'exposure',
            'payment_information_risk': 'High (employee bank account numbers '
                                        'exposed)'},
 'investigation_status': 'Ongoing',
 'motivation': 'Financial gain',
 'ransomware': {'data_exfiltration': 'Yes (540GB exfiltrated)',
                'ransomware_strain': 'Kairos'},
 'references': [{'date_accessed': '2024-09-16',
                 'source': 'Kairos ransomware group leak announcement'}],
 'regulatory_compliance': {'regulations_violated': ['Potential Privacy Act '
                                                    '1988 (Australia) '
                                                    'violations']},
 'threat_actor': 'Kairos ransomware group',
 'title': 'Kairos Ransomware Attack on Leisure Coast Kitchens',
 'type': 'Ransomware'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.